Btcpayserver
Btcpayserver Btcpay Server: vulnerabilidades y CVE
Btcpayserver Btcpay Server tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1149 | Media (5.4) | 0.55% | — | 2 mar 2023 | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0. |
| CVE-2023-0879 | Media (5.4) | 0.48% | — | 17 feb 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12. |
| CVE-2022-32984 | Alta (7.5) | 1.0% | — | 31 ene 2023 | BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the… |
| CVE-2023-0493 | Alta (8.8) | 7.9% | — | 26 ene 2023 | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. |
| CVE-2021-3830 | Media (5.4) | 0.56% | — | 26 sept 2021 | btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3646 | Media (6.1) | 0.77% | — | 10 sept 2021 | btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-29250 | Media (5.4) | 0.53% | — | 5 may 2021 | BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing. |
| CVE-2021-29248 | Media (5.3) | 0.82% | — | 5 may 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie. |
| CVE-2021-29247 | Media (5.3) | 1.2% | — | 5 may 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie. |
| CVE-2021-29246 | Media (6.7) | 1.5% | — | 5 may 2021 | BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload… |
| CVE-2021-29245 | Media (5.3) | 0.95% | — | 5 may 2021 | BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key. |
| CVE-2021-29251 | Media (6.5) | 0.79% | — | 1 abr 2021 | BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured. |
| CVE-2021-29249 | Alta (7.5) | 1.2% | — | 26 mar 2021 | BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability. |